Impact
A stored cross‑site scripting vulnerability exists in Esri Portal for ArcGIS versions 11.5 and earlier. The flaw allows a remote attacker with administrative privileges to inject malicious script that is stored and later executed within the victim’s browser when the content is viewed. This can lead to the execution of arbitrary client‑side code, potentially exposing sensitive data or enabling further attacks against authenticated users. The CVSS score of 5.5 places the vulnerability in the medium severity range.
Affected Systems
Affected systems are Esri Portal for ArcGIS deployments running any of the identified versions 11.1, 11.3, or 11.5. All users of those releases are advised to apply the vendor’s patch or upgrade to the latest long‑term support release, as the issue is fixed in newer versions.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, and the vulnerability requires the attacker to be a privileged administrator to perform the injection. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation activity is unknown. The attack vector is inferred to be remote, as the attacker can inject the script from any location using privileged access. Overall, the risk is moderate but mitigated by the requirement of administrative credentials.
OpenCVE Enrichment